How to Share Your CIS Safely: Sending a Client Information Sheet, Passport Copy, and KYC Documents the Right Way
← Back to Blog
July 13, 202612 min read

How to Share Your CIS Safely: Sending a Client Information Sheet, Passport Copy, and KYC Documents the Right Way

July 2026 | AltFunds Global
By Taimour Zaman, Founder, AltFunds Global Corp. (Toronto) and AltFunds Global AFG AG (Zurich)

Most people share their CIS the wrong way.

They fill out a Client Information Sheet, attach a passport copy, add a utility bill, include company documents, maybe drop in a bank letter, and then send the whole bundle by email. Sometimes to a broker. Sometimes to a lender. Sometimes to someone they met online a few days ago.

No two-factor authentication. No download control. No watermark. No audit trail. No NDA gate. No staged access. No idea who opened it, downloaded it, forwarded it, saved it, or shared it.

That is not how sensitive financial documents should move.

Your CIS is not just paperwork. It is often the first serious document in a capital transaction, a private credit review, an insurance wrap, a bank file, a KYC process, or a due diligence pack. So the real question is simple. How do you share your CIS correctly?

You share it with control. Not casually. Not desperately. Not to whoever asks.

What is a CIS?

A CIS usually means Client Information Sheet. In a financial transaction, it helps a reviewer understand who you are, what company you represent, what deal you are working on, how much capital you are seeking, what assets or contracts support the request, and who the key parties are.

A CIS may carry your name, company details, contact information, transaction summary, funding request, source of repayment, banking details, asset information, and ownership records. In many cases it travels with KYC documents: a passport copy, proof of address, company registration, corporate ownership documents, bank letters, financial statements, and proof of funds.

That is sensitive information. It should be shared like sensitive information.

Why should you not just email your CIS and passport copy?

Because email gives you almost no control once the file leaves your outbox.

After you hit send, you may not know who opened it, who forwarded it, who downloaded it, or whether it is now sitting in someone's personal downloads folder, cloud backup, shared inbox, or WhatsApp thread.

When you email a CIS and passport copy, you are not only trusting the person you sent it to. You are trusting their inbox, their assistant, their forwarding habits, their cybersecurity, their storage, and their future judgment. That is a lot of trust for documents that include your passport, your utility bill, your company records, and your banking details.

What is the correct way to share your CIS?

Through a secure data room or a controlled document portal.

A proper data room gives you control over who can access your information, which documents they can see, whether they can download, whether files are watermarked, whether questions stay inside the room, and whether access can be revoked.

A folder stores documents. A data room controls them. That difference is the whole point. If the transaction is serious, the document process should be serious too.

Does every CIS need a full enterprise data room?

No. This is where common sense matters.

For a small early-stage introduction, a full enterprise data room can feel heavy. A secure tracked link with expiry, email verification, watermarking, and downloads switched off may be enough for the first stage. For a serious lender, bank, insurer, investor, private credit fund, M&A buyer, or compliance team, a proper data room is the better standard.

The right approach is progressive disclosure. Start light. Open more as trust increases. Do not give everyone everything on day one.

What is progressive disclosure?

It means you release information in stages, and each party gets only what they need at that point in the process. A simple structure looks like this:

Stage 1: teaser or executive summary. Stage 2: basic CIS or transaction summary. Stage 3: corporate documents and supporting transaction documents. Stage 4: KYC documents, passport copy, proof of address, and sensitive financial documents. Stage 5: the full diligence file, only for serious and properly vetted parties.

This protects you, and it makes you look more professional. You are not hiding information. You are controlling the timing of disclosure. That is exactly how serious transactions work.

What documents belong in a CIS data room?

A strong room is organized clearly. A good structure looks like this.

1. Read Me First

A short welcome note explaining what the room contains, who prepared it, what the transaction is about, and who to contact with questions. A short video introduction can help. It makes the room feel human and organized.

2. Executive Summary

The first document most people should see. It explains the transaction, the funding request, the parties, the use of funds, the repayment source, and why the opportunity is financeable.

3. Client Information Sheet

The current CIS. Do not upload a pile of old versions unless they are clearly labelled. The reviewer should never have to guess which document is current.

4. Corporate Documents

Company registration, certificate of incorporation, ownership records, shareholder information, board resolutions, and signing authority.

5. Transaction Documents

Contracts, purchase agreements, invoices, receivables, project summaries, offtake agreements, and collateral documents that support the funding request.

6. Financial Documents

Financial statements, bank letters, proof of funds, asset statements, repayment schedules, and projections.

7. Identity and KYC Documents

Passport copy, driver's licence, proof of address, and utility bill. This folder gets the highest level of access control. Not everyone needs to see it at the beginning.

8. Reputation and Background Response

The folder most people forget, and the one that can save the transaction.

Why should your data room include a reputation-response folder?

Because serious reviewers search your name. They search your company, litigation, complaints, social media, old disputes, allegations, and fraud warnings. They search anything that helps them decide whether they trust you.

If they find something confusing, negative, false, outdated, or incomplete, they may form an opinion before you ever get to explain. So your room should include a folder called Reputation and Background Response. Inside, write something simple:

"When you search my name or company, you may find XYZ. Here is the background. Here is what happened. Here are the steps we took. Here are the supporting documents. Here is our current position."

This is not weakness. It is preparation. It shows you understand how real due diligence works. Do not let the internet tell your story without your response sitting beside it.

Keep the tone calm. Do not over-explain, do not sound defensive, and do not attack everyone involved. A professional version reads like this: "When you search my name or company, you may find references to XYZ. This section provides the background, supporting documents, and our current position. The matter relates to a brief explanation. We addressed it by the steps taken. Supporting documents are included below." That is enough. The goal is not to argue inside the room. It is to help a serious reviewer understand the facts quickly.

What security features should a CIS data room have?

The core set: two-factor authentication, NDA gating before access, granular permissions, view-only by default, download and print controls, dynamic watermarking, audit logs, version control, a Q&A module, redaction tools, access expiry, revocable access, exportable activity logs, and data residency options where needed. Depending on the provider and the deal, certifications such as SOC 2 Type II or ISO 27001 matter too.

None of this makes risk disappear. It raises the standard. In serious finance, raising the standard is the job.

Why does two-factor authentication matter?

Because a password alone is not enough. If someone has a link and a password, they may be able to walk straight into your documents. Two-factor authentication adds a second step to confirm that the person accessing the room is actually the intended person. Your CIS can carry enough to understand your identity, your company, your transaction, and your supporting files. That deserves more than a basic password.

Should people sign an NDA before seeing your CIS?

In many cases, yes. If the room holds sensitive identity documents, transaction documents, financial information, private company records, or reputation-response material, it is reasonable to require an NDA or access terms before anything is viewed. Many rooms let the viewer accept confidentiality terms before entering. That creates a record, and it filters unserious people. If someone refuses basic confidentiality, that tells you something. Serious people understand document control.

Should your CIS be downloadable?

Not by default. View-only at the beginning. The reviewer may need to see the file, but seeing it is not the same as being able to save it, print it, or forward it. Download access should be deliberate. If a bank, lender, compliance team, or law firm genuinely needs a downloadable copy, grant it at the proper stage, and record it. View-only first. Download only when necessary.

What is dynamic watermarking?

A dynamic watermark displays information about the person viewing the document: viewer name, email, date, time, IP address, session ID. That is very different from a static "Confidential" stamp. A static watermark says the file is confidential. A dynamic watermark says who viewed it.

That changes behaviour. When someone opens your passport copy or CIS and sees their own name printed across it, they understand the file is traceable. That creates accountability.

Can a data room stop someone taking a screenshot?

No system can fully stop someone photographing a screen with another phone. That is the honest answer. But a proper room can make screenshots and phone photos traceable. If the document carries a dynamic watermark, even a photo of the screen may show the viewer's name, email, access time, or session details. You are not only trying to block bad behaviour. You are creating evidence, and making it clear the document is tied to the person viewing it. That alone prevents a lot of careless sharing.

What is fence view?

Fence view limits what a person can see on screen at one time, to make casual screen capture harder. It is not perfect. Nothing is. But combined with dynamic watermarking, restricted downloads, audit logs, and access controls, it adds another layer. Security is not one tool. Security is layers.

Should you redact your passport before sharing it?

For early review, often yes. A redacted passport copy may be enough at first, depending on the purpose of the review and what the receiving party requires. Hide the information that is not needed yet, and provide the full copy only when a regulated party, compliance team, bank, or lawyer formally requires it.

This is data minimization. Share what is needed. Do not share what is not yet needed. When the process reaches a serious stage, provide the full document through the secure room or through the recipient's own secure portal.

What if a bank or lender requires its own portal?

Use it. Many regulated institutions will not accept KYC documents through your system. They require you to upload into their own secure portal. That is normal. The goal is not to be rigid. The goal is to be controlled. If the bank has a secure portal, use it. If the lender's compliance team requires a specific format, follow it. If they need download access from your room, give it to the right people, at the right stage, with the right record. Professional does not mean difficult. Professional means controlled and flexible.

Should brokers receive your passport and KYC documents?

Usually not at the beginning. A broker may need enough to understand the transaction, but that does not mean they need your passport, utility bill, bank statements, or full KYC file on day one. Give brokers a teaser, an executive summary, or a limited CIS first. Give lenders and regulated reviewers deeper access later. Give full KYC only when the receiving party has a legitimate reason to request it. Access should match the role. Not everyone deserves the same room.

What should you do before granting access?

Vet the recipient. Ask who they are, what company they represent, what their role in the transaction is, why they need the CIS, whether they will review it directly or forward it, whether they are authorized to evaluate the opportunity, and whether they will accept NDA-gated access through a secure room.

If they push back on basic security, that is useful information. It may mean they are not serious, not organized, or not the real decision-maker. Either way, you learned something before exposing your documents.

Should follow-up questions happen by email?

Ideally, no. For serious files, questions should stay inside the room's Q&A module or secure communication area. That ties questions to specific documents, records the answers, keeps versions clear, preserves the audit trail, and stops sensitive information leaking into long email chains. Email is convenient. Convenience is not control.

Why does version control matter?

Because serious transactions change. You update the CIS, replace a bank letter, upload a new financial statement, revise the transaction summary, add a legal document. If old versions sit in the room without labels, reviewers get confused. Use clean version names such as CIS v1.0, CIS v1.1, CIS v2.0 Current. Move superseded documents into an archive folder or remove them. A clean room creates confidence. A messy room creates doubt.

How long should access stay open?

Not forever. Set expiry dates. Review access regularly. Remove people who are no longer involved. Revoke access when the review is finished. Close the room if the transaction ends, and export the audit log if you need a record. Where the provider offers secure deletion certificates or confirmation of closure, keep those records. Good document control is not only about how you share the CIS. It is also about how you stop sharing it.

What if the deal is small?

Use judgment. A 500,000 dollar transaction may not need the same process as a 50 million dollar one. A trusted repeat relationship may not need the same friction as a new online introduction. The principle is not "use the most complicated process every time." It is "match the security to the risk." For early conversations, a secure tracked link may be enough. For serious diligence, use a proper data room. For regulated KYC, use the approved portal or secure upload. Secure by default. Practical in execution.

What does a professional CIS process say about you?

That you are organized. That you understand compliance. That you respect confidentiality. That you know how serious transactions work. That you are not desperate. Before someone funds a deal, underwrites a transaction, issues a term sheet, or introduces a capital source, they are reading signals. Your data room is one of them. A sloppy process creates doubt. A professional process creates confidence.

What is the biggest mistake people make with a CIS?

Treating sensitive documents like ordinary paperwork. A CIS is not ordinary paperwork. Neither is a passport copy, a utility bill, a bank letter, or corporate ownership information. These documents can be forwarded, copied, taken out of context, and misused, including by fraudsters. Mishandled, they create reputational problems. So do not send them casually. Share them with control.

The short answer

Share your CIS through a secure data room or controlled portal. Use progressive disclosure. Require two-factor authentication. Gate access with an NDA where appropriate. Disable downloads by default. Use dynamic watermarks. Track who viewed each file. Separate general documents from sensitive KYC. Redact where appropriate for early review. Keep questions inside the room. Maintain version control. Include a reputation and background response folder. Revoke access when the review is finished.

Most of all, stop treating your CIS like a casual attachment. It is the front door to your transaction. Share it like it matters.

Where we fit

We are a global financial advisory firm operating from Toronto and Zurich, working with institutional capital sources across North America, Europe, the Gulf, and select development finance institutions. We work with a broker network of more than 900 intermediaries on deals ranging from $1 million to $500 million, and the way a CIS and KYC pack is presented is often the first thing our desk and our capital partners judge.

Taimour Zaman is the Founder and Chief Capital Strategist of AltFunds Global. He is the author of Structured Finance Demystified and has been featured in TechTimes, Investment Executive, UK Entrepreneur, and Private Banker International.

Share

Ready to apply what you've read?

Start the 90-second Capital Concierge — no paperwork, no commitment.